Overview
Cyber security giant Fortinet confirmed a data breach after a threat actor claimed to have stolen 440 GB of files from the company’s Microsoft SharePoint server. Fortinet is known for its secure networking products and cyber security services.
Important findings
- A threat actor stole 440 GB of data from Fortinet’s Azure SharePoint instance.
- The stolen data was stored in an S3 bucket and made available to other threat actors.
- Fortinet has confirmed that customer data has been stolen from a “third-party cloud-based shared file drive.”
- Less than 0.3% of Fortinet’s customer base is affected.
- There was no malicious activity targeting customers.
- The incident did not involve data encryption, ransomware or access to Fortinet’s corporate network.
Details of the incident
A threat actor calling himself “Fortibitch” posted on a hacking forum that he stole 440 GB of data from Fortinet’s Azure SharePoint instance. The threat actor then shared credentials to an alleged S3 bucket that holds the stolen data so that other threat actors can download it.
Fortinet confirmed that an “individual has gained unauthorized access to a limited number of files on Fortinet’s instance of a third-party cloud-based shared file drive that contained limited data relating to a small number of Fortinet customers.”
Reaction of Fortinet
Fortinet has not disclosed how many customers are affected or what kind of data has been compromised, but said it has “communicated directly with affected customers.” A later update on Fortinet’s website stated that the incident affected less than 0.3% of the customer base and that there was no malicious activity targeting customers.
Previous incidents
In May 2023, a threat actor claimed to have hacked the GitHub repositories of Panopta, which was acquired by Fortinet in 2020, and published stolen data in a Russian-language hacking forum.
Sources
- Fortinet confirms data breach after hacker claims to steal 440GB of files, BleepingComputer.



